MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 446aad1d86aaf82a32f7e63bd0dd34cb2ac85ca2a412b9bea2122fb5506ddac1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gh0stRAT


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 446aad1d86aaf82a32f7e63bd0dd34cb2ac85ca2a412b9bea2122fb5506ddac1
SHA3-384 hash: c0a950a28e1d7840e4d5eb705a4d1ec5053a2d2b5d800595ffd630ed7af5ebcc83cb1523dcddd34a1f786ded559a4253
SHA1 hash: 57b83bd86c7d5c50fb5f895ec8b54abe059b626f
MD5 hash: 9859030f2303c9a1c1f423e2ab3d87a2
humanhash: hydrogen-vegan-pasta-aspen
File name:Government emergency notice.7z
Download: download sample
Signature Gh0stRAT
File size:22'475'317 bytes
First seen:2026-06-11 07:32:24 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 393216:cNg3L6YqqqZpRUA2S32yR+2YySuBMzX4DezJ7+irbqmQSPbnnaNNxcH2Q/Jqttv1:2g3sDytSmMlSu6zX4DqZbewbalO9SkEv
TLSH T1B037338A9FDFE8B2C8E701B34542132B81C23E55A356B23C8857B5F8675F16B146DB8C
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter smica83
Tags:7z Gh0stRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
HU HU
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Urgent Notice.exe
File size:22'999'121 bytes
SHA256 hash: ea78394ddfe75904bff4216eb05c618ee6ed3e5781e80b7f9acb9c7d2e2bdd9b
MD5 hash: 6d0c83cc8c323e9c7ef59f97a2fdb433
MIME type:application/x-dosexec
Signature Gh0stRAT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
95.7%
Tags:
virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context embarcadero_delphi fingerprint inno installer installer installer-heuristic packed reconnaissance
Verdict:
Malicious
File Type:
7z
First seen:
2026-06-10T04:21:00Z UTC
Last seen:
2026-06-10T04:34:00Z UTC
Hits:
~10
Gathering data
Gathering data
Threat name:
Win64.Trojan.Zmutzy
Status:
Malicious
First seen:
2026-06-10 09:29:36 UTC
File Type:
Binary (Archive)
Extracted files:
16
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery installer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Inno Setup is an open-source installation builder for Windows applications.
System Location Discovery: System Language Discovery
Executes dropped EXE
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments